Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.
| Score | Percentile |
|---|---|
| 0.10% | 26.46% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 4.4 | 3.0 | — |
|
| 6.7 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-v735-2pp6-h86r ↗ |
| CVE | CVE-2018-16859 ↗ |
| CWE id | Name |
|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| pip | ansible | >= 2.7.0a1, < 2.7.3 | 2.7.3 | — |
| pip | ansible | >= 0, < 2.5.12 | 2.5.12 | — |
| pip | ansible | >= 2.6.0a1, < 2.6.9 | 2.6.9 | — |